What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.
What I'd really like is a password manager hardware dongle of some kind, like the Bitcoin Trezor wallet.
[0]: The rebuttal for this will be signing every request with details of it with a hardware dongle, but would you want to do this for every action in your email client? If the answer is "no", you're owned. Ultimate security is unusable, and doesn't really solve anything outside of the most astute of professional users. Just writing this post I would need 4 signatures, one to log in, one to post, one to fix a typo, and yet another to add this footnote. Would I be able to handle that? No way, I'm far too lazy for that.
[1]: The issue is that perfect compromise is impossible to detect. I can be reasonably confident on a heavily sandboxed device like an iPhone that there's little in the way of malware that would affect me. The downside being that I have no tools or methods of analysis if I thought it was compromised. There's no such confidence on the computers I use on a daily basis. I've always thought we have confirmation bias with malicious software. We only notice the dumb stuff while the smart goes unnoticed.
For Bitcoin hardware wallets like Trezor, IIRC they either do or will support BIP-70 "Payment Protocol" payment requests that are signed with an X.509 cert, allowing you to verify the request on the dongle's screen.
I don't think signed addresses will be particularly effective. With the sort of key stores we have now, it seems pretty plausible that a bad actor to get a certificate that would pass on the Trezor device. It raises the barrier of entry a little though.
[0]: http://www.reddit.com/r/Bitcoin/comments/23sjle/chrome_exten....
[1]: http://www.reddit.com/r/Bitcoin/comments/1vrium/a_google_chr...
It'll basically push specialized requirements to the hardware dongle (ie deciding whether it's enough to confirm user registration/authorization with the touch of a buttom, or whether it needs to be with a 4 digit pin, or even with biometrics like voice or fingerprint or iris scan). The test device in the following presentation video only uses a button press to confirm user intent, but it could have arbitrary requirements, making the protocol usable for both trivial website logins to online banking to eventually perhaps even a replacement for defense department CACs.
Here's a good fairly in-depth video presentation of what the FIDO Alliance is working on (there are functional test devices, and a functional test branch of Chrome that works with them):